
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
|CircleCI|_ |Docs|_
.. |CircleCI| image:: https://circleci.com/gh/simplistix/testfixtures/tree/master.svg?style=shield .. _CircleCI: https://circleci.com/gh/simplistix/testfixtures/tree/master
.. |Docs| image:: https://readthedocs.org/projects/testfixtures/badge/?version=latest .. _Docs: http://testfixtures.readthedocs.org/en/latest/
Testfixtures is a collection of helpers and mock objects that are useful when writing automated tests in Python.
The areas of testing this package can help with are listed below:
Comparing objects and sequences
Better feedback when the results aren't as you expected along with support for comparison of objects that don't normally support comparison and comparison of deeply nested datastructures.
Mocking out objects and methods
Easy to use ways of stubbing out objects, classes or individual methods. Specialised helpers and mock objects are provided, including sub-processes, dates and times.
Testing logging
Helpers for capturing logging and checking what has been logged is what was expected.
Testing stream output
Helpers for capturing stream output, such as that from print function calls or even stuff written directly to file descriptors, and making assertions about it.
Testing with files and directories
Support for creating and checking both files and directories in sandboxes including support for other common path libraries.
Testing exceptions and warnings
Easy to use ways of checking that a certain exception is raised, or a warning is issued, even down the to the parameters provided.
Testing when using django
Helpers for comparing instances of django models.
Testing when using Twisted
Helpers for making assertions about logging when using Twisted.
FAQs
A collection of helpers and mock objects for unit tests and doc tests.
We found that testfixtures demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.